syncfusion-javascript-common

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PERSISTENCE]: The skill provides instructions for modifying shell profiles (such as ~/.bash_profile on macOS/Linux) to store license keys as environment variables. This technique ensures the environment variable persists across different shell sessions and system restarts.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents UI components like Grids and ListViews that interpolate data from a dataSource into HTML templates.
  • Ingestion points: dataSource properties in various UI controls as seen in SKILL.md and references/advanced-features.md.
  • Boundary markers: The examples provided do not show explicit delimiters or boundary markers to prevent the execution of instructions embedded within the data interpolated into templates.
  • Capability inventory: Capabilities include browser state persistence via localStorage, DOM manipulation, and instructions for shell command execution for licensing and configuration.
  • Sanitization: The skill references security guidelines and HTML sanitization in its documentation, but the provided code examples do not demonstrate active sanitization of the interpolated data within the skill's own snippets.
  • [COMMAND_EXECUTION]: The documentation includes shell commands for project setup and license activation, such as npx syncfusion-license activate, setx, export, and platform-specific commands like cordova run.
  • [EXTERNAL_DOWNLOADS]: The skill references downloads for official packages and themes from the npm registry, GitHub repositories (github.com/SyncfusionExamples), and the vendor's CDN (cdn.syncfusion.com). These are standard resources provided by the vendor for library integration and are documented neutrally.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 10:55 PM
Security Audit — agent-trust-hub — syncfusion-javascript-common